The serious debate on artificial intelligence is no longer about promises. It is about evidence. An organisation can say it uses AI that is responsible, safe, explainable or aligned with ethical principles; none of those words is auditable on its own. The auditor's question is more uncomfortable: what document, record, accountable person, test, log or verifiable decision supports the statement? This report structures that agenda for Argentina and Latin America with a declared evidence cut-off — May 2026 · ISO/IEC 42001, NIST AI RMF, EU AI Act and Argentina's AAIP instruments. Its output is the minimum dossier a board can demand this week.

The speed of adoption is already settled — the region adopts quickly, and report 17 in this series documents this with primary sources. What remains unresolved is everything else: ensuring that each adoption comes with an inventory, an owner, traceability, acceptance criteria and a real capacity for correction. That is the agenda.

The regional problem goes beyond regulation

The usual temptation is to reduce the subject to a legal question: whether there is a law or whether one is lacking. That reading falls short. The region already has general rules on data protection, transparency, consumer rights, civil liability, public procurement, information security and state administration, alongside specific guides and recommendations on artificial intelligence. The problem goes beyond the absence of a perfect text. It is the gap between declared principles and the operational controls an organisation can demonstrate.

A company that incorporates AI to assess customers, prioritise complaints, select candidates, summarise medical records, detect fraud or assist contractual decisions is already operating a decision-making system, whether it calls it that or not. If it cannot explain scope, data, purpose, limitations, accountable people, human oversight and a complaints mechanism, the risk is not in the future. It is already present.

AI is governed through evidence. Intent leaves no record.

Three layers that must not be conflated

Governance maturity requires separating three layers that are often confused. The recurring error in practice is using one layer to conceal another: an ethical guide does not substitute for technical controls, a technical framework does not replace legal responsibility, and management system certification does not in itself prove that each model is correct, fair or suitable for any use. The full comparison of the frameworks — scope, nature, effective dates, whom they bind — is in report 01 of this series. The following table arranges them by function, with the column almost no one reads: what each one does not resolve.

LayerReference frameworkWhat it resolvesWhat it does not resolve
Management systemISO/IEC 42001:2023Policies, roles, inventory, risks, controls, monitoring and improvement of AI use · verifiable and certifiable architectureThe correctness, fairness or legal adequacy of each specific model
Technical riskNIST AI RMFCommon language for bias, drift, explainability and robustness throughout the life cycle · a bridge between technical, legal, data and audit teamsThe management system that supports it and legal responsibility
Legal and sectoral complianceEU AI Act and Digital Omnibus adopted by the EU Council on 29 June 2026 · applicable legislation and AAIP instruments in ArgentinaApplicable obligations according to jurisdiction, sector, role, use and dateThe actual operational functioning of declared controls

The board dossier · ten questions with expected evidence

Before approving a consequential use of AI, the board need only demand a minimum decision dossier. The technical laboratory is on another floor. The dossier answers ten questions. Each has expected evidence, and that evidence is a dated document — not a verbal explanation at the meeting.

No.QuestionExpected evidence
01What system is used?Inventory with version, provider and registration date
02For what decision?Purpose authorised in writing, with scope and limitations
03With what data?Data map with a legal or contractual basis
04Who administers it?Named operational lead
05Who accepts the risk?Identifiable signatory with documented authority
06Which provider is involved?Contract, data processing agreement and supplier register
07What tests were carried out before production?Performance and bias results dated before deployment
08What human oversight is in place?Sampling criteria, authority to block and a record of blocks
09What record is kept of each significant decision?Traceability accessible to a third party
10What process corrects errors, biases or incidents?A procedure with an owner, a deadline and a case log

If those questions have no written answers, the organisation has no AI governance. It has informal trust in a tool. For low-impact uses, that may be tolerable. For decisions affecting rights, access to services, money, employment, safety, health, education or institutional reputation, the dossier is a prerequisite, not paperwork to be completed afterwards.

What an AI audit examines

An AI audit reviews the dossier and the operations behind it. It starts with the system inventory — which is only real with a prior amnesty, as established by Criterion 10 —, risk classification, authorised purpose, data map and change control. It then moves down to operations: performance testing, bias assessment, supplier management, human oversight, decision traceability, complaint channels, post-production monitoring and withdrawal or suspension criteria. There is just one focus: whether the organisation can prevent, detect, explain and correct errors before they become repeated harm. The difference between a technological incident and an institutional failure often lies in that response capability.

Argentina · fragmented instruments, growing demands

Argentina has instruments in force that can be cited. Provision 2/2023 approved recommendations for trustworthy artificial intelligence. AAIP Resolution 161/2023 created the specific programme for transparency and personal data protection in the use of AI. The AAIP's 2024 guide provides criteria on impact assessment, multidisciplinary teams, explainability, data protection and the full lifecycle. These instruments do not, in themselves, create a general legal obligation for every organisation: they help in requesting and designing evidence. Specific obligations depend on the applicable jurisdiction, sector, role, use and data processing. Evidence is built before a dispute arises.

Latin America · from copying regulations to achievable control

Many regional conversations about AI reproduce European or North American frameworks without adapting them to local capabilities. This transfer serves as a reference but fails as implementation. A bank, a province, a university, a healthcare company or an employment platform needs to turn that architecture into feasible controls · inventory, owners, records, human review, metrics, contracts, auditing and evidence. Latin America's opportunity does not lie in competing for the most ambitious regulatory text. It lies in creating management systems that demonstrate how AI is used under real conditions — budget constraints, supplier dependence, incomplete data, uneven institutional capabilities.

The defensible minimum

Operational brief

The defensible minimum

For organisations already using AI, the defensible minimum is an evidence base with ten elements · an inventory of uses · impact classification · an owner for each system · authorised purpose · data assessment · a supplier register · pre-production testing · subsequent monitoring · a human review channel · an incident procedure.

That minimum does not eliminate risk. It makes it governable. And when an auditor, regulator, judge, client or citizen asks what was done to prevent harm, the organisation will be able to respond with records rather than a promise.

When someone serious asks what was done to prevent harm, the answer will be the dossier — or it will be a promise.